A vulnerability described as critical has been identified in OpenReception appointment-booking-software up to 1.0.5. The affected element is an unknown function of the file /api/tenants/{id}/appointments/bootstrap-challenge of the component Bootstrap Challenge. The manipulation of the argument tunnelId/clientPublicKey/emailHash results in allocation of resources.
This vulnerability is reported as CVE-2026-48082. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.